Detecting and Preventing Rogue AP Attacks

  • Large Network
    • Monitor the frequency band for unauthorized access points using the WIPS (Wireless Intrusion Protection System)
    • WIPS tracks down rogue APs based on channel, MAC address, and SSID
  • Small Network
    • Manually create a list of allowed APs based on MAC address and detect APs that are not allowed
    • Can use tools like AirMagnet or NetStumbler
  • Only connect to networks you know
  • Register all soft APs